Audit-Trail uses electronic signatures?


If a PLC / SCADA system uses an audit trail, and if someone changes the value of a parameter or a state of a valve, and the user enters a correct “user name” and password, this action is stored in a database, including the user name associated to the action.

The question is: when the user accepts the action typing his “user name” and password, and all this information is available in a printed report, this could be considerate like a electronic signature?

According to the FDA: “Persons who use electronic signatures based upon use of identification codes in combination with passwords shall employ controls to ensure their security and integrity.”

In other words, a username/password identification is considered an electronic signature if it complies with certain controls. You can find details about these controls here:

